Sceawere

Vulnerability Detail

CVE-2026-108730UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Raven Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
4h ago
Vendor
The-Commit-Company
Product
raven
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Raven 2.0.0 through 3.0.0 contains a missing authorization vulnerability in legacy methods in raven/api/raven_message.py that skip the workspace membership check. Authenticated non-members can call get_messages_with_dates or get_all_files_shared_in_channel with predictable channel IDs to read Public channel history and Open/Public channel file metadata across workspaces.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T13:17:17.067Z",
  "pubdate": "2026-10-11T13:17:17.067Z",
  "executiveSummary": "Raven versions 2.0.0 through 3.0.0 are affected by a critical missing authorization vulnerability residing in legacy API methods. The flaw allows authenticated, non-member users to bypass workspace membership validation checks, granting unauthorized access to sensitive information across different workspaces.\nThe vulnerability is classified as an Improper Authorization defect. By targeting predictable channel identifiers, an attacker can exfiltrate public channel history and file metadata, effectively violating workspace isolation boundaries. This exposure poses a significant risk to organizational data confidentiality, as non-authorized individuals can perform reconnaissance and data harvesting without requiring elevated administrative privileges.\nExploitation requires the attacker to hold a valid, authenticated account within the platform, though they do not need to be a member of the specific workspace targeted. Because the vulnerable methods do not verify the caller's membership status against the requested workspace, the system treats the malicious request as legitimate, provided the attacker can guess or obtain the target channel IDs.",
  "technicalDetails": "The root cause of this vulnerability lies in the implementation of legacy API methods within raven/api/raven_message.py. Specifically, the functions get_messages_with_dates and get_all_files_shared_in_channel lack the mandatory authorization middleware or internal logic required to enforce workspace-scoped membership validation. In standard operation, any request to access workspace resources should verify that the authenticated user's session identifier is explicitly associated with the requested workspace context.\nIn the affected versions (2.0.0 through 3.0.0), these functions skip the authorization check, acting as a blind entry point for data retrieval. An attacker with a valid session can invoke these legacy endpoints to query channel data. Because the API relies on predictable channel IDs, an attacker can systematically iterate through known or discoverable ID patterns to request message histories and file metadata for public channels in workspaces to which they do not belong.\nThe attack flow proceeds as follows: First, the attacker identifies the API endpoints exposed by raven/api/raven_message.py. Second, the attacker formulates HTTP requests to these endpoints, specifying the targeted, predictable channel IDs. Third, the backend, failing to cross-reference the user's current session permissions against the workspace's access control list, processes the request and returns the serialized channel history or file metadata. This bypass effectively ignores the security boundary intended to segment information flow between different organizational workspaces.\nThe exploitation surface is limited to authenticated users, meaning external unauthenticated attackers cannot reach these endpoints directly. However, the requirement for an authenticated account is minimal, as standard user registration often grants access to the platform's API surface. The impact is significant, as it facilitates unauthorized disclosure of internal communication and sensitive file metadata. Because the vulnerability exists within legacy code paths, it underscores a failure to maintain consistent authorization policies across the codebase, allowing deprecated or overlooked functions to circumvent the security controls implemented in modern, updated modules."
}
CVE-2026-108730: Raven Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere